iSee857
106 exploits
Active since Mar 2024
Tomcat Partial PUT Java Deserialization
nginxui/nginx_ui < 2.3.3 - Unauthenticated Sensitive Data Exposure via Backup Endpoint
dedecms 5.71sp1 - URL Redirection via GET Request
Commvault Command Center Innovation Release <11.38.20 - Path Traversal
DataEase < 2.10.10 - Improper Authentication via JWT Secret Bypass
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L - OS Command Injection via nas_sharing.cgi System Parameter
Cisco IOS XE - Unauthenticated Arbitrary File Upload and Remote Code Execution via Hard-coded JWT
Apache NiFi 1.10.0-2.0.0 - Authenticated Missing Authorization for Parameter Contexts and Controller Services
FlowiseAI Flowise <= 2.2.6 - Arbitrary File Upload
NovaCHRON Smart Time Plus <8.6 - SQL Injection
Kubio AI Page Builder <2.5.1 - Local File Inclusion
Checkout Mestres do WP for WooCommerce <8.7.5 - Privilege Escalation
NovaCHRON Smart Time Plus <8.7 - SQL Injection
OpenCode <1.0.216 - Command Injection
Altenergy Power Control Software <20241108 - SQL Injection
CrushFTP - Authentication Bypass
Apache Solr 5.3.0-8.11.3 and 9.0.0-9.6.9 - Authentication Bypass via Fake URL Path Ending
Apache Tomcat 9.0.0-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - RCE via TOCTOU Race Condition in JSP Compilation
AstrBot 3.4.4-3.5.12 - Path Traversal and Information Disclosure via Dashboard Feature
Baiyi Cloud Asset Management System <8.142.100.161 - SQL Injection
Brother/Konica/Toshiba Printers - Default Admin Password Generation
Multiple Brother devices authentication bypass via default administrator password generation
crmeb 5.4.0 - Arbitrary File Read via save_basics Function
Cleo Harmony, VLTrader, and LexiCom < 5.8.0.21 - Unrestricted File Upload and Remote Code Execution
DataEase < 2.10.2 - Use of Hard-coded Credentials for JWT Forgery